Anthropic has released a troubling look at how powerful AI tools are being pushed into dangerous territory. Its September 2026 Threat Intelligence report reveals cases involving biological research, weapons development, cyber operations targeting Ukraine, surveillance, fraud, and attempts to copy Claude’s advanced capabilities.
The report covers malicious or suspicious activity that Anthropic investigated and disrupted over roughly eight months. It does not claim that Claude independently launched these operations. Instead, people used or attempted to use the model as a tool inside larger projects, sometimes while trying to bypass Anthropic’s safeguards and access restrictions.
The AI giant says its threat intelligence team studies these real-world cases so it can identify weak points and strengthen its defenses.
Claude Appeared in Biological and Weapons Research

One researcher used infrastructure to access Claude from a region where Anthropic does not officially provide its services.
That researcher spent weeks working on plans involving avian influenza experiments, according to reporting on Anthropic’s findings. Other cases involved viruses, toxins, and related biological research. However, Anthropic stressed an important limitation: It did not claim that every scientist involved intended to create a biological weapon.
This distinction is crucial because biological science contains plenty of ‘dual-use research’. The term describes legitimate research that can produce useful scientific knowledge but could also create security risks if applied for harmful purposes. The same technical information can therefore sit in an uncomfortable space between medical research and dangerous misuse.
Anthropic responded by banning accounts connected with the cases and feeding what it learned into its safety systems. The larger concern is not that an AI model automatically turns ordinary researchers into weapons experts. It is that increasingly capable models may reduce some of the knowledge barriers that once made highly specialized work harder to perform.
The report also describes Claude’s use in conventional weapons-related work. Anthropic separately reported that advanced models are becoming capable of helping with some military and intelligence tasks that once required scarce human expertise. These areas include software, engineering, targeting, surveillance, and systems connected with weapons.
Russia-Linked Hackers Put Claude Into Cyber Operations

The operation reportedly used Claude across several stages of its activity.
According to reports, the group’s methods were consistent with those associated with Midnight Blizzard, a threat actor that the United States has linked to Russia’s Foreign Intelligence Service. The reported targets centered heavily on Ukraine, European organizations, government bodies, and companies connected with military drone technology and supply chains.
One reported system could detect when malicious code triggered security defenses and then revise that code. That kind of automation matters because cyber operations usually require repeated testing and adjustment. AI can potentially shorten parts of that cycle by helping operators analyze failures and modify their approach more quickly.
‘Model distillation’ uses a stronger teacher model to generate answers that help train another model. Anthropic defines ‘illicit distillation’ as covertly extracting another model’s capabilities at industrial scale without authorization. The company says operators used fraudulent accounts and proxy networks to gain access to Claude.
Alibaba accounted for the biggest campaign described in the report. Anthropic says operators affiliated with Alibaba generated more than 151 million exchanges with Claude between May and July 2026. Activity reportedly peaked at almost three million exchanges per day and involved thousands of fraudulent accounts.
Anthropic alleges that the operation targeted Claude’s reasoning, coding, software engineering, and agent capabilities to improve Alibaba’s Qwen models. These remain Anthropic’s allegations based on its own investigation.